Aggregator
CVE-2022-23913 | Apache ActiveMQ Artemis up to 2.19.0 resource consumption (Nessus ID 235116)
CVE-2022-40150 | Jettison XML Parser resource consumption (Issue 45 / Nessus ID 235116)
CVE-2022-0084 | Oracle Communications Cloud Native Core Console 22.3.0 Configuration denial of service (Nessus ID 235116)
CVE-2022-0084 | XNIO notifyReadClosed allocation of resources (Nessus ID 235116)
Hackers Exploit 21 Apps to Take Full Control of E-Commerce Servers
Cybersecurity firm Sansec has uncovered a sophisticated supply chain attack that has compromised 21 popular e-commerce applications, granting hackers full control over hundreds of online stores. This malicious campaign, which began with the injection of backdoors as early as six years ago, was activated this week, exposing vulnerabilities in software from vendors such as Tigren, […]
The post Hackers Exploit 21 Apps to Take Full Control of E-Commerce Servers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Arabian Ghosts Defaced the Website of Massage Fitness Health Studio and Shop
Q1 2025 Recap: GitGuardian Doubles Down on Secrets Security and Machine Identity Control
GitGuardian launches new NHI Governance, enhanced synergies with Secret Manager integrations, smarter context analysis, container registry scanning, historical scanning for Jira & Confluence, and more. Take control of your secrets security, and machine identities.
The post Q1 2025 Recap: GitGuardian Doubles Down on Secrets Security and Machine Identity Control appeared first on Security Boulevard.
Alleged Sale of Admin and Shell Access to an Unidentified Greek E-Commerce Website
Hackers Target HR Departments With Fake Resumes to Spread More_eggs Malware
The financially motivated threat group Venom Spider, also tracked as TA4557, has shifted its focus to corporate Human Resources (HR) departments with a highly targeted spear-phishing operation. According to research by Arctic Wolf Labs, the group is leveraging legitimate job platforms and messaging services to send fraudulent job applications laced with malicious resumes. These deceptive […]
The post Hackers Target HR Departments With Fake Resumes to Spread More_eggs Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
UK shares security tips after major retail cyberattacks
Submit #564591: https://github.com/megagao/production_ssm production_ssm <= 0.0.1 Remote Code Execute [Accepted]
Submit #564339: PHPGurukul Company Visitors Management System V2.0 SQL Injection [Accepted]
RomCom RAT Targets UK Organizations Through Compromised Customer Feedback Portals
The Russian-based threat group RomCom, also known as Storm-0978, Tropical Scorpius, and Void Rabisu, has been targeting UK companies in the retail, hospitality, and critical national infrastructure (CNI) sectors in a recently discovered cyber espionage and profit-driven operation called “Operation Deceptive Prospect.” Active since at least 2022, RomCom has a history of blending espionage with […]
The post RomCom RAT Targets UK Organizations Through Compromised Customer Feedback Portals appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Submit #564329: SourceCodester Online-Student-Clearance-System 1.0 SQL Injection [Accepted]
Submit #571379: magento 1.9.2.1 Improper Input Validation [Accepted]
Hackers Use Pahalgam Attack-Themed Decoys to Target Indian Government Officials
The Seqrite Labs APT team has uncovered a sophisticated cyber campaign by the Pakistan-linked Transparent Tribe (APT36) targeting Indian Government and Defense personnel. This operation, centered around the recent Pahalgam terror attack on April 22, 2025, leverages emotionally charged themes to distribute phishing documents and deploy malicious payloads. Exploiting Geopolitical Tensions for Cyber Espionage The […]
The post Hackers Use Pahalgam Attack-Themed Decoys to Target Indian Government Officials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Submit #564318: 74cms 74cms se 3.33 RCE [Accepted]
BSidesLV24 – Proving Ground – An Adversarial Approach To Airline Revenue Management
Author/Presenter: Craig Lester
Our sincere appreciation to BSidesLV, and the Presenters/Authors for publishing their erudite Security BSidesLV24 content. Originating from the conference’s events located at the Tuscany Suites & Casino; and via the organizations YouTube channel.
The post BSidesLV24 – Proving Ground – An Adversarial Approach To Airline Revenue Management appeared first on Security Boulevard.